RLS
Row-level security
Database rules that decide which rows a given user can see, enforced by the database itself.
Rather than trusting every query in the application to filter correctly, the database refuses to return rows the current user is not entitled to. It fails closed, and it keeps working when somebody adds a new query and forgets the filter.
Switched on is not the same as correct. In ooruby's own audit of apps built with Lovable (ooruby App Audit #1, on the research page), no sampled app left a table without row-level security in its migrations, yet some had policies that let any caller change or delete every row.
A policy that allows every caller everything leaves the switch reading on while the table is open to anyone, which is worse than off, because nobody looks again.
Testing with one account. Row-level security bugs are invisible until a second user exists.
Related terms
See RLS on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue